Standard Bank suffers data leak
Standard Bank says it has been impacted by an incident in which personal information of clients was subject to “unauthorised access” on 23 March 2026, with external experts now investigating.
The bank, the largest in South Africa by assets, told MyBroadband that the unauthorised access did not impact its banking systems, which remain secure and operational.
It initially announced the incident in a press release published to its newsroom titled “A message from Standard Bank.” The company has also begun notifying impacted customers, it said.
“The Standard Bank of South Africa has identified an incident involving unauthorised access to select data, and we immediately took steps to secure our environment and mitigate the impact,” it said in March.
“Our teams, supported by experts, have launched a full investigation into this incident. We operate within a robust regulatory framework and fully comply with all applicable obligations.”
In an update provided to MyBroadband, the bank said information such as names and surnames, ID numbers and company registration numbers has been affected by the incident.
However, Standard Bank said that the specific information involved may differ from person to person. “We will directly notify the select number of clients that are affected,” it said.
“We have increased our monitoring and encourage our clients to remain vigilant.”
Standard Bank explained that it continues to strengthen controls and enhance monitoring in line with industry best practices to protect clients’ information. It warns clients to beware of fraudulent activity.
“Given the nature of the information accessed, there is a risk that someone could use it to try to impersonate you or contact you fraudulently,” it said. This could be done via email, calls, or SMS.
This is a technique called spear-phishing, where cybercriminals use specific information that is leaked online or exfiltrated via a system breach to target victims with unique lures.
For example, an attacker could use your name, surname, ID number and the name of your company to craft a unique attack designed to convince you to input your banking details in a fraudulent website.
Standard Bank said it has also reported the incident to the regulatory authorities. The Information Regulator of South Africa is the country’s primary authority for data breaches and leaks.
Liberty data breach disclosed on the same day

The incident at Standard Bank took place on the same day as life insurer and investment provider Liberty disclosed a security breach where unauthorised actors gained access to internal systems.
Liberty is a major subsidiary of the Standard Bank Group and is integrated into the bank’s broader financial services across 16 African markets.
“Liberty recently detected unauthorised access to your personal information. Your policies and investments remain secure and our services are running normally,” it said at the time.
Liberty CEO Yuresh Maharaj said that the company’s services remain unaffected, fully operational, and available to all clients, advisors, and employees.
“Our team, supported by experts, has launched a full investigation into this incident. We operate within a robust regulatory framework and fully comply with all applicable obligations,” he said.
Standard Bank urged clients to follow a number of security best practices following the incident as a precaution, including:
- Update passwords on banking apps and social media
- Enable digital two-factor authentication on the mobile banking app
- Contact your relationship manager immediately if you notice suspicious activity on your card or accounts
- Never share your personal information, including passwords and PINs, when asked to do so via phone, text, or email
- Use strong, unique passwords and use biometric authentication where possible
- Register with the Southern African Fraud Prevention Service for protective registration, which is a free service
- Verify any unexpected email, SMS or call asking for sensitive information by contacting the bank
Standard Bank also said customers should, as always, avoid clicking on suspicious links or unfamiliar website URLs.